Revolut Denies Ransom Demand After Alleged Data Leak Claims

Revolut has stated that it did not receive any direct contact or negotiation requests from the group alleging a customer data breach, despite public claims demanding 6,000 XMR (approximately $3 million) to prevent the sale of stolen information. A representative confirmed on the 17th that no such communication was received.
The group identifying itself as 'IAmNotAVillain' publicly demanded 6,000 XMR within 24 hours, threatening to sell customer records to other criminal organizations if unpaid. The demand emerged shortly after news of the alleged data breach became public.
Attackers reportedly accessed customer information via government agency email accounts rather than directly infiltrating core systems. Alleged leaked data included addresses, contact details, transaction histories, and identity documents affecting around 680 customers, though Revolut confirmed no compromise to user accounts or funds.
Another group, 'Revolut Smilik,' reportedly demanded 10,000 BTC (approximately $78 million) for a similar breach. IAmNotAVillain denied being part of this claim, stating that other groups were falsely taking credit for partial data access.
Cybersecurity account Dark Web Informer linked another website, revoloot.lol, to separate attackers associated with the incident. Both websites were inaccessible at the time of reporting.
Italian authorities are investigating whether government email accounts were compromised in the breach, with the National Anti-Mafia and Counter-Terrorism Agency involved. The investigation focuses on unauthorized access to public computer systems and potential exposure of KYC data held by financial institutions.
Korean Source
This article is an English localization of a Korean-language crypto news report. Original headline: 리볼루트, 모네로 6000개 공개 요구에도 직접 연락 없어